{"schema_version":"1.9.0","id":"CVE-2022-28948","published":"2022-05-19T19:59:30Z","modified":"2026-08-12T03:51:13.833332197Z","aliases":["GHSA-hp87-p4gw-j4gq","GO-2022-0603"],"related":["CGA-c83p-wfx4-qxwj","SUSE-SU-2025:02998-1","SUSE-SU-2025:02999-1","SUSE-SU-2025:03000-1","SUSE-SU-2025:03001-1","SUSE-SU-2026:22997-1","openSUSE-SU-2024:0319-1","openSUSE-SU-2024:12490-1","openSUSE-SU-2025:15510-1","openSUSE-SU-2025:15529-1","openSUSE-SU-2026:21457-1"],"details":"An issue in the Unmarshal function in Go-Yaml v3 causes the program to crash when attempting to deserialize invalid input.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/go-yaml/yaml","events":[{"introduced":"00bbc0947ae889b9e480044dbc3bc3e3216a6a89"},{"last_affected":"00bbc0947ae889b9e480044dbc3bc3e3216a6a89"}],"database_specific":{"cpe":"cpe:2.3:a:yaml_project:yaml:3.0.0:*:*:*:*:go:*:*","extracted_events":[{"introduced":"3.0.0"},{"last_affected":"3.0.0"}],"source":"CPE_STRING"}}],"versions":["3.0.0","v3.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-28948.json"}}],"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/28xxx/CVE-2022-28948.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-28948"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20220923-0006/"},{"type":"REPORT","url":"https://github.com/go-yaml/yaml/issues/666"}],"database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/28xxx/CVE-2022-28948.json"}}